Results 1 to 8 of 8
  1. #1
    Experienced User
    Overall activity: 0%

    Join Date
    Jul 2009
    Location
    Kolkata , West Bengal , India
    Posts
    1,559
    Liked
    54 times
    Points
    18,175

    IE8 bug makes 'safe' sites unsafe

    The latest version of Microsoft's Internet Explorer browser contains a bug that can enable serious security attacks against websites that are otherwise safe.

    The flaw in IE 8 can be exploited to introduce XSS, or cross-site scripting, errors on webpages that are otherwise safe, according to two Register sources, who discussed the bug on the condition they not be identified. Microsoft was notified of the vulnerability a few months ago, they said.

    Ironically, the flaw resides in a protection added by Microsoft developers to IE 8 that's designed to prevent XSS attacks against sites. The feature works by rewriting vulnerable pages using a technique known as output encoding so that harmful characters and values are replaced with safer ones. A Google spokesman confirmed there is a "significant flaw" in the IE 8 feature but declined to provide specifics.

    It's not clear how the protections can cause XSS vulnerabilities in websites that are otherwise safe. Michael Coates - a senior application security engineer at Aspect Security who has closely studied the feature but was unaware of the vulnerability - speculates it may be possible to cause IE 8 to rewrite pages in such a way that the new values trigger an attack on a clean site.

    "If the attacker can figure out a flaw in the way IE 8 is actually doing that output encoding and then create a specific string the attacker will know will be transformed into an actual attack, they could use that to input a value ... that actually results in an attack firing on the page," he said. "This could be a way to introduce an attack into a page that didn't have a vulnerability otherwise."

    XSS attacks are a way of manipulating a site's URL to inject malicious code or content into a trusted webpage. Many security watchers have come to view the IE 8 protections as Microsoft's answer to NoScript, a popular extension that helps prevent XSS and other types of attacks against users of the Firefox browser.

    Late on Thursday afternoon, Microsoft told The Register: "Microsoft is investigating new public claims of a vulnerability in Internet Explorer. We're currently unaware of any attacks trying to use the claimed vulnerability or of customer impact."

    Once its investigation is finished, the company will "take appropriate action," including issuing a patch or guidance on how users can protect themselves against exploits.

    When Microsoft introduced the protections, it also created a way for webmasters to override the feature (by adding the response header "X-XSS-Protection: 0"). A review of the top 50 most visited websites shows that only web properties owned by Google have actually opted to do so. The small number of sites blocking the protection calls into question how widespread the vulnerability is.

    Asked why Google was forgoing the protection, a company spokesman wrote in an email:

    "We're aware of a significant flaw affecting the XSS Filter in IE8, and we've taken steps to help protect our users by disabling the mechanism on our properties until a fix has been released." He didn't elaborate.
    Full Story.

  2. #2
    Modern-day Romeo
    Overall activity: 18.0%

    Join Date
    Jul 2009
    Location
    Singapore, the "Little Red Dot" on the map
    Posts
    6,159
    Liked
    476 times
    Points
    60,895
    I'm not an IE fan and am not using IE8...but I'm wondering it the same flaw is found in IE7.
    They call me the mysterious one...
    my motto is...when it's hot, chill baby

  3. #3
    Tech God
    Overall activity: 0%

    Join Date
    Jan 2008
    Location
    South Africa
    Posts
    1,279
    Liked
    14 times
    Points
    1,853
    As long as IE stays the most popular browser it will be exploited.

  4. #4
    Experienced User
    Overall activity: 0%

    Join Date
    Oct 2009
    Posts
    521
    Liked
    0 times
    Points
    10,125
    My friends have got lots of bad stuff happened to their compiter cause on IE thats why i use FF because it's safer
    Amature Programmer.
    Beginner Firefox add-on and toolbar Developer.

  5. #5
    Modern-day Romeo
    Overall activity: 18.0%

    Join Date
    Jul 2009
    Location
    Singapore, the "Little Red Dot" on the map
    Posts
    6,159
    Liked
    476 times
    Points
    60,895
    Quote Originally Posted by Odie View Post
    As long as IE stays the most popular browser it will be exploited.
    IE isn't the most popular browser...it's the most widely used browser due to the fact that it is pre-installed on Windows machines and that many have no idea there are better alternatives to it...

    Firefox is the most popular browser...people CHOOSE to use it.

  6. #6
    Tech God
    Overall activity: 0%

    Join Date
    Jan 2008
    Location
    South Africa
    Posts
    1,279
    Liked
    14 times
    Points
    1,853
    Quote Originally Posted by safeguy View Post
    Firefox is the most popular browser...people CHOOSE to use it.
    You are so right.

  7. #7
    Moderator
    Overall activity: 73.0%

    Join Date
    Dec 2008
    Location
    Italy
    Posts
    6,895
    Liked
    1067 times
    Points
    71,755
    IE 8 is not affected

    http://msmvps.com/blogs/donna/archive/2009/11/24/microsoft-security-advisory-977981-ie8-is-not-affected.aspx

  8. #8
    Modern-day Romeo
    Overall activity: 18.0%

    Join Date
    Jul 2009
    Location
    Singapore, the "Little Red Dot" on the map
    Posts
    6,159
    Liked
    476 times
    Points
    60,895
    I want to point out that Internet Explorer 8 is not affected on any platform and that running Protected Mode in Internet Explorer 7 on Windows Vista mitigates this issue.
    Protected Mode is enabled on IE7 on my Vista...

 

 

Similar Threads

  1. Windows Safe Mode Fixer: Repair Safe Mode
    By sujay in forum Security Bulletin
    Replies: 3
    Last Post: 07-20-2011, 10:32 AM
  2. Replies: 0
    Last Post: 07-03-2010, 08:07 PM
  3. this video makes me crack up
    By Kazemagic in forum Chat
    Replies: 8
    Last Post: 04-18-2009, 06:31 PM
  4. This makes me think twice???
    By saturn in forum Chat
    Replies: 13
    Last Post: 03-21-2009, 07:48 AM
  5. what makes their prices different?
    By kwfine in forum Music (DJ)
    Replies: 1
    Last Post: 06-24-2007, 09:49 PM
All times are GMT +8. The time now is 03:42 AM.